Back to results

Abertay University

Intrusion Detection Systems using Machine Learning and Deep Learning techniques

Abstract

dc:description.abstract

The increased reliance on networked technologies has led to a digital transformation of general- and special-purpose networks that further interlace technologies and heterogeneous systems. The ever-evolving technological landscape of interconnected devices constantly expands the network attack surface, which has contributed to the number and complexity of cyber attacks in recent years. The analysis of network traffic through Intrusion Detection Systems (IDS) has become an essential element of the networking security toolset. To cope with the increased rate and complexity of cyber attacks, researchers have utilised Machine Learning (ML) and Deep Learning (DL) techniques to develop IDS to cope with new and zero-day attacks. However, the lack of large, realistic, and up-to-date datasets hinders the IDS development process. <br/><br/>This thesis proposes an empirical investigation of ML and DL algorithms to detect known and unknown attacks in general- and special-purpose networks. The thesis further investigates how ML and DL algorithms can learn from a limited amount of data while retaining high accuracy. To this effect, a special-purpose IoT dataset is generated and evaluated against six ML techniques. The challenges and limitations of identifying anomalies in special-purpose networks are identified and discussed. <br/><br/>In an attempt to reduce the need for large training datasets, this thesis investigates the utilisation of Few-Shot learning paradigm to train IDS using a limited amount of data. For this purpose, Siamese networks are used and evaluated in three scenarios. This thesis further investigates the use of autoencoders to detect zero-day attacks.<br/>The zero-day attack detection experiments highlight the problem of discriminating benign-mimicking attacks. To overcome this challenge, an additional layer of feature abstraction is proposed; to improve accuracy through the cumulative aggregation of network traffic.<br/><br/>The results of this research demonstrate the effectiveness of the proposed approaches for IDS development. Siamese networks demonstrate their ability to learn from limited data. The proposed autoencoder models exhibit their potential to detect zero-day attacks. Finally, the significance of flow aggregation features in discriminating benign-mimicking attacks is demonstrated.

Degree

thesis:*
Name dc:type.qualificationname
PhD
Level dc:type.qualificationlevel
Doctoral Thesis
Grantor dc:publisher.institution
Abertay University
Year dc:date.issued
2021

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Hindy, Hanan
Advisors dc:contributor.advisor
  • Coull, Natalie
  • Bayne, Ethan
  • ElSayed, Salma
  • Bellekens, Xavier

Rights

Language dc:language
eng

Identifiers

dc:identifier.*
Identifier
oai:rke.abertay.ac.uk:studenttheses/838780f5-b506-4d3a-b98d-c1cb9180beec
OAI identifier oai:identifier
oai:rke.abertay.ac.uk:studenttheses/838780f5-b506-4d3a-b98d-c1cb9180beec

Chain of custody

source
Harvested from
Abertay University
Base URL
rke.abertay.ac.uk/ws/oai
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Hindy, Hanan. Intrusion Detection Systems using Machine Learning and Deep Learning techniques. Doctoral Thesis thesis, Abertay University, 2021. https://rke.abertay.ac.uk/en/studentTheses/838780f5-b506-4d3a-b98d-c1cb9180beec